Privacy Policy
Last updated: September 22, 2026
This Privacy Policy explains what information the Reelferry browser extension (“the extension”, “we”, “us”) handles and how. The extension runs entirely inside your browser. We operate no backend service, and we do not collect, store, sell, or share your personal information or your Google user data.
Information the extension handles
Google account and YouTube data
When you connect YouTube, you sign in through Google's OAuth flow and choose which channel to use. You can repeat this to connect several channels. For each connected channel the extension receives an access token and basic channel information (such as the channel name, thumbnail, and statistics) so it can display that channel and upload videos on your behalf. These tokens are stored locally in your browser, one per channel, and are used only to read channel details and to upload videos to the channel you select.
Disconnecting a channel removes it and its token from your browser and asks Google to revoke that token. Your upload history for that channel remains on your device until you delete it.
Google API scopes
Signing in grants the extension these scopes, and nothing more:
- youtube.upload — to upload the video you select to the channel you choose.
- youtube.readonly — to list the channels you own, so you can pick a destination and set a default. We do not read your videos, playlists, comments, subscriptions, or analytics.
- openid, userinfo.email, userinfo.profile — to identify which Google account a connected channel belongs to, so you can tell several connected channels apart.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Instagram session information
To fetch the media for a Reel you choose to repost, the extension reads the session identifier from your active, signed-in Instagram tab and stores it locally in your browser. When you fetch a Reel, this session identifier and the Reel's URL are sent to a third-party media service (socialdownloader.in), which returns the video and its details. We do not use this session identifier for any other purpose.
Reel content and upload details
The video and metadata for a Reel you choose to process (such as its caption, which you can edit into a title, description, and tags) are handled locally to prepare the upload and are then sent to YouTube using your authorized token when you choose to post.
Upload history and settings
The extension keeps a local history of Reels you've posted — including links to the original Reel and the resulting Short, and which channel it was posted to (its name and thumbnail) — to help you avoid accidental duplicates and to let you filter your history by channel. The channel details recorded with an upload are kept even after that channel is disconnected, so your history stays readable. Your extension settings, such as your default tags and default channel, are stored alongside it. This information is stored locally in your browser.
Information we do not collect
- We do not run analytics, tracking pixels, or advertising networks.
- We do not sell or rent your information.
- We do not receive your passwords — sign-in happens through Google and Instagram directly.
How information is used
- To detect the Reel you're viewing and fetch its media.
- To display your connected YouTube channels.
- To upload videos to the channel you select, with the details you provide.
- To keep a local record of what you've posted so you can avoid duplicates.
How information is shared
We do not share, transfer, sell, rent, or disclose your Google user data to anyone. The access tokens, channel details, email address, and basic profile information obtained through the Google API scopes above never leave your device except to travel to Google's own APIs, and only to carry out an action you asked for — listing your channels, or uploading a video you chose to post. We operate no backend, so there is no server of ours that receives, holds, or forwards this data.
The only transfer to a party other than Google is unrelated to your Google account: when you fetch a Reel, its URL and your Instagram session identifier are sent to socialdownloader.in so it can return the media. That request contains no Google user data of any kind.
- No Google user data is shared with analytics, advertising, or data-broker services.
- No subprocessors, contractors, or human reviewers — including us — have access to your Google user data.
- We would disclose information only where required by law, which cannot arise for your Google user data, because we never hold it.
How information is protected
Sensitive information — your Google access tokens and your Instagram session identifier — is protected by the following measures:
- Local, sandboxed storage. Tokens, the session identifier, your upload history, and your settings are held in the browser's extension storage, which Chrome isolates to this extension's ID. Web pages and other extensions cannot read it. The temporary Reel cache lives in session storage, which is held in memory and discarded when the browser closes.
- Encryption in transit. Every network request the extension makes uses HTTPS/TLS. The extension declares HTTPS-only host permissions, so it cannot make an unencrypted request at all.
- Least privilege. We request only the scopes listed above — no more. Tokens are issued and stored per channel, so a token can only ever act on the single channel it belongs to.
- Token lifecycle. Access tokens are short-lived, are never logged, and are never sent anywhere other than Google. Disconnecting a channel deletes its token from your device and calls Google's revocation endpoint to invalidate it.
- No server to breach. Because there is no backend holding Google user data, there is no central store that could be compromised.
- Your control. Uninstalling the extension removes everything it stored, and you can revoke its access at any time from your Google Account permissions.
Where information is stored
Your per-channel access tokens, captured session identifier, upload history, and settings are stored locally in your browser's extension storage. They remain on your device and are not transmitted to any server operated by us.
Third-party services
Using the extension involves the following third parties, each governed by its own privacy policy:
- Google / YouTube — for authentication and to upload videos. See the Google Privacy Policy.
- socialdownloader.in — a media service that receives a Reel's URL and your Instagram session identifier in order to return the Reel's media.
- Instagram / Meta — the source of the Reels you browse. See the Instagram Privacy Policy.
Permissions
The extension requests only the permissions it needs to function, including:
- identity, identity.email — to sign in to Google and connect your YouTube channels, and to show which Google account each connected channel belongs to.
- storage, unlimitedStorage — to save your tokens, connected channels, history, and settings locally, without a size cap on a long upload history.
- sidePanel, activeTab, tabs — to run the side panel and detect the active Reel tab.
- webRequest — to read your Instagram session identifier so media can be fetched.
- notifications — to tell you when background uploads succeed or fail.
- Host access to Instagram, its content delivery networks, socialdownloader.in, and Google APIs — to fetch media and perform uploads.
Data retention and deletion
Because data is stored locally, uninstalling the extension removes its stored data from your browser. You can also revoke the extension's access to your Google account at any time from your Google Account permissions.
Children's privacy
The extension is not directed to children under 13, and we do not knowingly collect information from children.
Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the “Last updated” date above.
Contact
Questions about this policy? Email us at contact@tcmhack.com.